目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-26974— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 困难 EPSS 0.19% · P9

可能的 ATT&CK 技术 1AI

T1059.004 · Unix Shell

影响版本矩阵 20

厂商产品版本范围状态
LinuxLinuxd8cba25d2c68992a6e7c1d329b690a9ebe01167d< daba62d9eeddcc5b1081be7d348ca836c83c59d7affected
d8cba25d2c68992a6e7c1d329b690a9ebe01167d< 8e81cd58aee14a470891733181a47d123193ba81affected
d8cba25d2c68992a6e7c1d329b690a9ebe01167d< d03092550f526a79cf1ade7f0dfa74906f39eb71affected
d8cba25d2c68992a6e7c1d329b690a9ebe01167d< 4ae5a97781ce7d6ecc9c7055396535815b64ca4faffected
d8cba25d2c68992a6e7c1d329b690a9ebe01167d< 226fc408c5fcd23cc4186f05ea3a09a7a9aef2f7affected
d8cba25d2c68992a6e7c1d329b690a9ebe01167d< 8a5a7611ccc7b1fba8d933a9f22a2e76859d94dcaffected
d8cba25d2c68992a6e7c1d329b690a9ebe01167d< 0c2cf5142bfb634c0ef0a1a69cdf37950747d0beaffected
d8cba25d2c68992a6e7c1d329b690a9ebe01167d< bb279ead42263e9fb09480f02a4247b2c287d828affected
… +12 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-26974 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
crypto: qat - resolve race condition during AER recovery
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - resolve race condition during AER recovery During the PCI AER system's error recovery process, the kernel driver may encounter a race condition with freeing the reset_data structure's memory. If the device restart will take more than 10 seconds the function scheduling that restart will exit due to a timeout, and the reset_data structure will be freed. However, this data structure is used for completion notification after the restart is completed, which leads to a UAF bug. This results in a KFENCE bug notice. BUG: KFENCE: use-after-free read in adf_device_reset_worker+0x38/0xa0 [intel_qat] Use-after-free read at 0x00000000bc56fddf (in kfence-#142): adf_device_reset_worker+0x38/0xa0 [intel_qat] process_one_work+0x173/0x340 To resolve this race condition, the memory associated to the container of the work_struct is freed on the worker if the timeout expired, otherwise on the function that schedules the worker. The timeout detection can be done by checking if the caller is still waiting for completion or not by using completion_done() function.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于内存释放后重用。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux d8cba25d2c68992a6e7c1d329b690a9ebe01167d ~ daba62d9eeddcc5b1081be7d348ca836c83c59d7 -
LinuxLinux 3.17 -

二、漏洞 CVE-2024-26974 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-26974 的情报信息

登录查看更多情报信息。

CVE-2024-26974 邮件列表归档 (2)

CVE-2024-26974 其他参考 (8)

同批安全公告 · Linux · 2024-05-01 · 共 159 条

CVE-2024-27038Linux kernel 安全漏洞
CVE-2024-27029Linux kernel 安全漏洞
CVE-2024-27030Linux kernel 安全漏洞
CVE-2024-27031Linux kernel 安全漏洞
CVE-2024-27032Linux kernel 安全漏洞
CVE-2024-27033Linux kernel 安全漏洞
CVE-2024-27034Linux kernel 安全漏洞
CVE-2024-27035Linux kernel 安全漏洞
CVE-2024-27036Linux kernel 安全漏洞
CVE-2024-27037Linux kernel 安全漏洞
CVE-2024-27044Linux kernel 安全漏洞
CVE-2024-27048Linux kernel 安全漏洞
CVE-2024-27047Linux kernel 安全漏洞
CVE-2024-27046Linux kernel 安全漏洞
CVE-2024-27045Linux kernel 安全漏洞
CVE-2024-27041Linux kernel 安全漏洞
CVE-2024-27039Linux kernel 安全漏洞
CVE-2024-27040Linux kernel 安全漏洞
CVE-2024-27028Linux kernel 安全漏洞
CVE-2024-27043Linux kernel 安全漏洞

显示前 20 条,共 159 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26974

暂无评论


发表评论